Skip to content

Need support on the SonarQube flagged security issues on latest magento framework. Do we need to fix these , are these severe? #39737

Open
@i4msur4nj4n

Description

@i4msur4nj4n
<style> </style>
Message Type Severity Language File
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/editableMultiselect/js/jquery.multiselect.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/jquery.metadata.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/jquery.tabs.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/jquery.tabs.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/spectrum/spectrum.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/spectrum/tinycolor.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/spectrum/tinycolor.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/ui-modules/effect-fold.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/ui-modules/sortable.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/ui-modules/tabs.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/jquery/ui-modules/widget.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/adminhtml/grid.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/adminhtml/varienLoader.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/tinymce4Adapter.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/tinymce4Adapter.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/tinymce4Adapter.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/widget.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/backend/form.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/backend/tabs.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/requirejs/text.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/requirejs/text.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/mage/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/moment.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/prototype/validation.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/requirejs/require.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/requirejs/require.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/requirejs/text.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/requirejs/text.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/scriptaculous/effects.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/classes/html/Styles.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/classes/html/Styles.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/plugins/advlink/js/advlink.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/plugins/style/js/props.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/themes/advanced/js/color_picker.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/utils/form_utils.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/tiny_mce/utils/form_utils.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/varien/js.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/varien/js.js
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service. CRITICAL JavaScript lib/web/varien/js.js
Make sure this permission is safe.   MAJOR PHP setup/src/Magento/Setup/Model/Cron/Status.php
Make sure this permission is safe.   MAJOR PHP update/app/code/Magento/Update/Rollback.php
Make sure this permission is safe.   MAJOR PHP update/app/code/Magento/Update/Rollback.php
Make sure this permission is safe.   MAJOR PHP update/app/code/Magento/Update/Rollback.php
Make sure this permission is safe.   MAJOR PHP update/app/code/Magento/Update/Status.php
This image might run with root as the default user. Make sure it is safe here.   MINOR Docker Dockerfile
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/extjs/ext-tree-checkbox.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/jquery/editableMultiselect/js/jquery.editable.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/jquery/jquery.metadata.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/jquery/jquery.metadata.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/mage/adminhtml/grid.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/mage/requirejs/static.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/mage/utils/template.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/mage/utils/template.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/modernizr/modernizr.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/prototype/validation.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/requirejs/require.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/classes/Popup.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/underscore.js
Make sure that this dynamic injection or execution of code is safe.   CRITICAL JavaScript lib/web/varien/form.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/fotorama/fotorama.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/jquery/colorpicker/js/colorpicker.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/jquery/spectrum/spectrum.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/jquery/spectrum/spectrum.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/jquery/spectrum/spectrum.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/mage/backend/suggest.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/mage/utils/misc.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/mage/utils/misc.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/prototype/prototype.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/prototype/window.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/prototype/window.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/scriptaculous/effects.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL JavaScript lib/web/underscore.js
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP lib/internal/Mageplaza/Hybrid/Providers/LinkedIn.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OAuth/OAuth.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/BundleProductsFixture.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/ConfigurableProductsFixture.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/ImagesGenerator/ImagesGenerator.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/ImagesGenerator/ImagesGenerator.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/ImagesGenerator/ImagesGenerator.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/OrdersFixture.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/OrdersFixture.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/OrdersFixture.php
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/plugins/magentovariable/editor_plugin.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/plugins/magentovariable/editor_plugin.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/plugins/magentowidget/editor_plugin.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/mage/adminhtml/wysiwyg/tiny_mce/plugins/magentowidget/editor_plugin.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/requirejs/require.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/classes/firebug/firebug-lite.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/advlink/js/advlink.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/autosave/editor_plugin_src.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/autosave/editor_plugin_src.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/media.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/media.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/media/js/media.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/preview/jscripts/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/preview/jscripts/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/preview/jscripts/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/preview/jscripts/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/plugins/preview/jscripts/embed.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/themes/advanced/js/link.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_jquery_src.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_prototype_src.js
Using http protocol is insecure. Use https instead.   CRITICAL JavaScript lib/web/tiny_mce/tiny_mce_src.js
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/Providers/AOL.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/Providers/Twitter.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/Providers/Twitter.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/Providers/Twitter.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OpenID/LightOpenID.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Model/PhpReadinessCheck.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Model/PhpReadinessCheck.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Module/Di/Code/Scanner/XmlScanner.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Console/Command/InstallStoreConfigurationCommandTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Console/Command/InstallStoreConfigurationCommandTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Controller/UrlCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Controller/UrlCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Controller/UrlCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Controller/UrlCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Controller/UrlCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/PhpReadinessCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/PhpReadinessCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/PhpReadinessCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/PhpReadinessCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/PhpReadinessCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/PhpReadinessCheckTest.php
Using http protocol is insecure. Use https instead   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Mvc/Bootstrap/InitParamListenerTest.php
Make sure that this logger's configuration is safe.   CRITICAL PHP update/app/bootstrap.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP lib/internal/Mageplaza/Hybrid/thirdparty/OAuth/OAuth.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/AttributeSet/SwatchesGenerator.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/ImagesFixture.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/ImagesGenerator/ImagesGenerator.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Model/ConfigOptionsList/Cache.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Model/ConfigOptionsList/PageCache.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Model/CryptKeyGenerator.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigOptionsList/CacheTest.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigOptionsList/PageCacheTest.php
Make sure this weak hash algorithm is not used in a sensitive context here.   CRITICAL PHP setup/src/Magento/Setup/Test/Unit/Module/ConfigGeneratorTest.php
Make sure using this hardcoded IP address is safe here.   MINOR PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigGeneratorTest.php
Make sure using this hardcoded IP address is safe here.   MINOR PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigOptionsList/LockTest.php
Make sure using this hardcoded IP address is safe here.   MINOR PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigOptionsList/LockTest.php
Make sure using this hardcoded IP address is safe here.   MINOR PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigOptionsListTest.php
Make sure using this hardcoded IP address is safe here.   MINOR PHP setup/src/Magento/Setup/Test/Unit/Model/ConfigOptionsListTest.php
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/install-extension-grid.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/landing.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/marketplace-credentials.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/popupauth.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/readiness-check/progress.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/success.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/success.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/success.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML setup/view/magento/setup/update-extension-grid.phtml
Make sure not using rel="noopener" is safe here.   MINOR HTML update/app/code/Magento/Update/view/templates/status.phtml
Make sure the "PATH" used to find this command includes only what you intend.   MINOR JavaScript dev/tools/grunt/tasks/deploy.js
Make sure the "PATH" used to find this command includes only what you intend.   MINOR JavaScript dev/tools/grunt/tasks/deploy.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Review this potentially hardcoded credential.   BLOCKER JavaScript setup/pub/magento/setup/create-admin-account.js
Make sure that recursively copying directories is safe here.   CRITICAL Docker Dockerfile
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/PriceProvider.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/PriceProvider.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/SimpleProductsFixture.php
Make sure that using this pseudorandom number generator is safe here.   CRITICAL PHP setup/src/Magento/Setup/Fixtures/SimpleProductsFixture.php
Make sure that this logger's configuration is safe.   CRITICAL PHP app/bootstrap.php

Metadata

Metadata

Assignees

Labels

Issue: On HoldReported on 2.4.xIndicates original Magento version for the Issue report.Triage: Dev.ExperienceIssue related to Developer Experience and needs help with Triage to Confirm or Reject it

Type

No type

Projects

Status

On Hold

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions